Executive brief
Multiple DrayTek VigorSwitch network switches contain a buffer overflow vulnerability in their diagnostic pingtrace function. An attacker with valid administrative credentials can send specially crafted input to overflow a fixed-size buffer, causing the device to crash or potentially execute arbitrary commands. This impacts the availability and security of critical network infrastructure.
Technical details
A buffer overflow vulnerability exists in the pingtrace function of the VigorSwitch web management interface. The vulnerability occurs when host, count, and interval parameters are concatenated into a fixed-size buffer without proper length validation. An authenticated remote attacker can trigger this via crafted input to the web interface, causing denial of service (device crash/reboot) or potentially arbitrary code execution on the appliance. Patches are available for all affected models; exploitation requires valid administrative credentials to access the web management interface.
Affected products
- DrayTek VigorSwitch G2540xs before 3.9.10
- DrayTek VigorSwitch P2540xs before 3.9.10
- DrayTek VigorSwitch FX2120 before 3.9.10
- DrayTek VigorSwitch G2282x before 2.10.6
- DrayTek VigorSwitch P2282x before 2.10.6
- DrayTek VigorSwitch Q2300x before 2.10.7
- DrayTek VigorSwitch PQ2300xb before 2.10.7
- DrayTek VigorSwitch G2542x before 3.10.6
- DrayTek VigorSwitch P2542x before 3.10.6
- DrayTek VigorSwitch P2542xh before 3.10.6
- DrayTek VigorSwitch PX2060 before 2.9.10
- DrayTek VigorSwitch G1280 before 2.9.10
- DrayTek VigorSwitch P1280 before 2.9.10
- DrayTek VigorSwitch P1281x before 2.9.10
- DrayTek VigorSwitch G1282 before 2.9.10
- DrayTek VigorSwitch P1282 before 2.9.10
- DrayTek VigorSwitch G2121 before 2.9.10
- DrayTek VigorSwitch P2121 before 2.9.10
- DrayTek VigorSwitch PQ2121x before 2.9.10
- DrayTek VigorSwitch Q2121x before 2.9.10
- DrayTek VigorSwitch G2280x before 2.9.10
- DrayTek VigorSwitch P2280x before 2.9.10
- DrayTek VigorSwitch Q2200x before 2.9.10
- DrayTek VigorSwitch PQ2200xb before 2.9.10
- DrayTek VigorSwitch G2100 before 2.9.10
- DrayTek VigorSwitch P2100 before 2.9.10
- DrayTek VigorSwitch G2540x before 2.9.10
- DrayTek VigorSwitch P2540x before 2.9.10
Timeline
- 2026-08-24: disclosed: Publicly disclosed by DrayTek security advisory DSA-2026-003
- 2026-08-24: patched: Firmware patches released for all affected models